Trending Topics

AI moves in milliseconds, rendering check-the-box security audits useless
According to Pathlock’s new AI Governance Gap Report, 23% of organisations have already been hit by one or more AI-related security incidents.
Given that enterprises are rushing to deploy AI agents in critical business processes, and with the recent OpenAI/Hugging Face furore still firmly front and centre of the AI security debate, this should come as no real surprise.
Nor, for that matter, is the fact that 51% of the organisations polled by Pathlock said that they “aren’t confident” that they even know all of the AI agents that are operating within their systems. 31% weren’t even sure if there have been security incidents involving them or not.
This state of affairs cannot continue. At least not if you really mean it when you say, post the inevitable breach, that you take security seriously.
“Three forces are converging – the explosion of identities, increasingly interconnected business applications, and AI agents that can now execute business processes autonomously at machine speed,” said Chris Radkowski, a governance, risk and compliance expert at Pathlock.
Key findings of the Pathlock AI Governance Gap Report
The report fully supports Radkowski’s sentiments, finding:
- 38% of organisations allow AI agents to create and modify business records
- 36% have already embedded or are currently implementing AI agents in finance and accounting
- 28% allow AI agents to approve transactions
- 35% allow AI agents to execute cross-system workflows
- 28% allow AI agents to approve transactions
If those numbers don’t concern you, then you need to get out of the security business and into the sea.
Ram Varadarajan, CEO at Acalvio, told me that the answer to AI problem is AI. “Reactive defences cannot operate at machine speed, necessitating a shift in the cybersecurity stack to preemptive, AI-driven strategies,” he warned, adding that this means “AI fighting AI, combined with offensive deception technologies.”
Doing that is the best way we’ve yet found to catch attackers off guard and cause them to make mistakes and reveal themselves.
What isn’t an option any longer, and hasn’t really ever been, is check-the-box security auditing. This, alongside general-purpose AI audits are, Varadarajan concluded, “a false comfort when the actual battle is moving in milliseconds”.
Time to up your AI governance game
He’s not wrong. According to Pathlock’s Susan Stapleton, 79% of organisations have no dedicated AI governance team or officer, 52% can’t verify actions Al agents execute across business systems, and 48% can’t trace AI agent activity end-to-end across systems.
“The investigation gap is particularly acute,” Stapleton warned. “If a questionable AI-driven action were flagged today, only 13% of organisations could investigate it in real-time, and only 18% could complete an investigation within hours. Nearly a quarter could not reliably investigate at all.”
As AI agents become more common, organisations should also start treating them as privileged identities, according to Shane Barney, Chief Information Security Officer at Keeper Security.
“That means clearly defined operational boundaries, least-privilege access, continuous monitoring and a complete audit log of everything they touch,” Barney advised. “Autonomous systems work best when paired with human oversight and strong governance frameworks.”
Have I already said that this state of affairs simply cannot continue?
More security articles by Davey Winder
- Hugging Face attack isn’t an AI wake-up call, it’s a Security 101 lesson
- Microsoft’s record-breaking Patch Tuesday is a vulnerability itself
- Check your kernel version now: 15-year-old security ghost in the Linux machine
- When AI agents attack: JADEPUFFER agentic ransomware raid deploys AI from start to finish
